Vulnerabilities > Netjuke

DATE CVE VULNERABILITY TITLE RISK
2007-09-11 CVE-2007-4811 Cross-Site Scripting vulnerability in Netjuke 1.0Rc2
Multiple cross-site scripting (XSS) vulnerabilities in Netjuke 1.0-rc2 allow remote attackers to inject arbitrary web script or HTML via (1) the val parameter to alphabet.php in an alpha.albums action, or the PATH_INFO to (2) random.php or (3) admin/hidden.php.
network
netjuke CWE-79
4.3
2007-09-11 CVE-2007-4810 SQL Injection vulnerability in Netjuke 1.0Rc2
Multiple SQL injection vulnerabilities in Netjuke 1.0-rc2 allow remote attackers to execute arbitrary SQL commands via (1) the ge_id parameter in a list.artists action to explore.php or (2) the id parameter in a show.tracks action to xml.php.
network
low complexity
netjuke CWE-89
7.5
2002-12-31 CVE-2002-2114 Remote Command Execution vulnerability in Netjuke
Artekopia Netjuke before 1.0 b7 allows remote attackers to execute arbitrary code on the web server, possibly via the section parameter, which is passed to an eval call.
network
low complexity
netjuke
7.5